Forge cloud apps that meet the Atlassian Enterprise Certified (AEC) program requirements can apply for certification.
This guide explains how to prepare your app, run the pre-submission validation scan, resolve any issues, and submit your application.
To access an AEC application, you must:
If a team member needs access:
Marketplace Partner account roles sync to the ticket once per day. After the sync adds the team member to Partner Participants, they can access the AEC Scorecard.
Review the current AEC requirements and validation methods. Make sure that your app meets the requirements before you start an application.
Confirm that your app, operational processes, and trust center documentation are ready for validation.
Use the approved document naming conventions in the Required Documentation section. The validation scanner uses these conventions to identify documents in your trust center.
Complete this preparation before applying. If the pre-submission validation scan finds that your app does not meet the requirements, you won't be able to submit the application.
For each app that you submit, provide:
To create an AEC application:
Include every app that you want reviewed when you create the ticket. There are options to add and remove apps, so this is flexible.
After you create the ticket, you can navigate to the AEC Scorecard and trigger a scan. The ticket receives a comment when the scan is complete.
Open AEC Scorecard from the app list in the top-right area of the application ticket.
The scorecard:
A failed requirement means the scan completed and found an unmet requirement. It doesn't mean that the scan itself failed.
Use the following scorecard views:
For a non-passing requirement, select Show remediation details to review:
Publish any required app changes before requesting another scan. Keep in mind that it may take up to 24 hours for this new version to be available to the scorecard.
You can start a new assessment in either of these ways:
A rescan creates a new assessment; it doesn't resume the previous scan. Until a newly published version becomes available to the scanner, results can continue to reflect the previous build.
Trust center and AI policy review
Your public trust center must use a supported provider. See requirement 3.1 in the AEC program requirements for the current list.
Vanta and SafeBase trust centers are checked automatically. Trust centers hosted by another supported provider require manual review.
If your supported trust center requires manual review, you can submit the application after all automated checks unrelated to the trust center have passed. Atlassian reviews the trust center documentation, including the AI usage policy for requirement 5.1, during application review.
If your trust center provider isn't on the list, the trust center checks will fail and you will not be able to submit the
If you dispute a non-passing requirement, find the app's results in the AEC Scorecard and select Request exception.
In the request:
The exception request and supporting evidence are shared with Atlassian for review.
Exception requests are intended for cases where the scanner:
An exception request isn't a substitute for meeting a requirement. Requests based only on an unmet requirement will generally be rejected.
Approved exceptions count toward your scorecard result.
A requirement failure and a scan-processing failure are different:
If the app shows Scan failed, you can request another scan or select Report scan failure in the scorecard app.
After you report the failure, the affected app displays Waiting for Atlassian. Atlassian reviewers receive the restricted technical error details.
The Apply to AEC button becomes available when:
Select Apply to AEC to move the application to Under Review. Atlassian then validates the results.
If Atlassian needs more information or remediation, the team will use the ECOHELP ticket to explain the gap and discuss next steps.
After approval, Atlassian adds the AEC badge to the app's Marketplace listing.
When a scan completes, Atlassian adds a comment to the application ticket containing:
Use this information to confirm that Atlassian assessed the app build that you intended to submit.
It can take up to 24 hours for a newly published app version to become available to the scanner.
To add an app after creating an AEC application, create a separate application ticket for that app.
You don't need to formally remove an app that you no longer want to submit. In the AEC Scorecard, choose which apps you want to scan and submit. Leave an app unselected if you don't want it included.
Request an exception when you believe the scanner has missed valid evidence or incorrectly marked a requirement as unmet. In the AEC Scorecard, select Request exception beside the app's results, choose each result you want reconsidered, and provide an explanation with supporting links or evidence.
Don't request an exception when your app simply doesn't meet the requirement. Make the required changes, publish a new app version if necessary, and request another scan.
For a trust center check, confirm that the document name follows the required naming conventions.
For other checks:
Atlassian scans certified apps daily for the requirements that were checked during onboarding. The checks may change over time.
If Atlassian detects a violation, you will receive an ECOHELP ticket that identifies the affected app and requirement. You have 30 days from detection to remediate the violation before Atlassian takes enforcement action.
Atlassian offers a managed penetration testing program in collaboration with Bugcrowd. See the Marketplace Penetration Testing Program to get started.
Atlassian offers eligible Marketplace Partners a subsidy for a one-year subscription to Vanta's core offering. The offering includes:
See the Partner Compliance Program Quick Reference Guide for details.
Rate this page: